6.4
CVSSv2

CVE-2014-3864

Published: 30/05/2014 Updated: 29/12/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote malicious users to modify files outside of the intended directories via a crafted source package that lacks a --- header line.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian dpkg-dev 1.3.0

Vendor Advisories

A malicious source package could write files outside the unpack directory ...
Debian Bug report logs - #746498 dpkg-source: Directory traversal on unpack through missing --- header line Package: dpkg-dev; Maintainer for dpkg-dev is Dpkg Developers <debian-dpkg@listsdebianorg>; Source for dpkg-dev is src:dpkg (PTS, buildd, popcon) Reported by: javier--7C8FrOsBhwV6hRgYM4mLHJBYcgPTm9@jaspnet Date: W ...
Debian Bug report logs - #749183 dpkg-source: Directory traversal on unpack through Index: pseudo-header Package: dpkg-dev; Maintainer for dpkg-dev is Dpkg Developers <debian-dpkg@listsdebianorg>; Source for dpkg-dev is src:dpkg (PTS, buildd, popcon) Reported by: Guillem Jover <guillem@debianorg> Date: Sat, 24 May ...
Multiple vulnerabilities were discovered in dpkg that allow file modification through path traversal when unpacking source packages with specially crafted patch files This update had been scheduled before the end of security support for the oldstable distribution (squeeze), hence an exception has been made and was released through the security arc ...